Friday, September 11, 2026

Adobe ColdFusion Critical Vulnerabilities Enable Arbitrary Code Execution

Adobe has released critical security updates for ColdFusion 2025 and ColdFusion 2023, addressing 17 vulnerabilities that could enable arbitrary code execution, privilege escalation, bypass of security features, denial-of-service attacks, and memory exposure.

This update, tracked as APSB26-90 and published on August 11, 2026, has been rated Priority 1 by Adobe, indicating that organizations should prioritize remediation as urgent.

At the time of publication, Adobe stated that there were no known instances of these vulnerabilities being exploited in the wild.

Adobe ColdFusion Critical Vulnerabilities

The updates affect ColdFusion 2025 versions 2025.0.11 and earlier, as well as ColdFusion 2023 versions 2023.0.22 and earlier, across all supported platforms.

Administrators are advised to upgrade ColdFusion 2025 deployments to version 2025.0.12 and ColdFusion 2023 deployments to version 2023.0.23.

Given the breadth and severity of these vulnerabilities, patching is especially crucial for internet-facing ColdFusion servers, which often host business applications, administrative portals, and database-connected workloads.

The most serious vulnerability, CVE-2026-48362, is an OS command injection flaw rated CVSS 10.0. This vulnerability arises from the improper neutralization of special elements used in operating system commands, allowing unauthenticated remote attackers to execute arbitrary code.

Its CVSS vector indicates low attack complexity, no required privileges or user interaction, and a high impact on confidentiality, integrity, and availability.

If exploited, this vulnerability could enable an attacker to execute operating system commands within the context of the ColdFusion service account, potentially leading to application compromise, data theft, lateral movement, or destructive activities.

Adobe also addressed CVE-2026-48273, a critical eval injection vulnerability with a CVSS score of 9.9. Although exploitation requires low privileges, it can still lead to arbitrary code execution with significant impacts on confidentiality, integrity, and availability.

Another notable issue, CVE-2026-71384, is an incorrect authorization vulnerability rated 9.6 that can lead to an application denial-of-service.

The bulletin acknowledges three researchers for their contributions: Anirudh Anand (aka a0xnirudh) for CVE-2026-71386, Matan Sandori (aka matans1) for CVE-2026-71384, and Brennan D. St. John (aka brennanstjohn) for CVE-2026-71387.

The bulletin highlights several authorization failures, input validation weaknesses, cryptographic issues, and a heap-based buffer overflow.

While some vulnerabilities may require local access, elevated privileges, user interaction, or adjacent-network positioning, they should not be considered low-priority in enterprise environments.

Attack chains can combine authentication weaknesses, security control bypasses, and code execution flaws, increasing the impact after initial access.

Adobe noted that, effective August 11, 2026, it may assign a single CVE identifier to internally discovered vulnerabilities that share the same severity rating and CWE category when releases include systemic fixes.

As such, security teams should consider the fixes as potential remediation for multiple related code paths rather than assuming each CVE represents a single isolated defect.

In addition to patching, Adobe recommends using the latest compatible MySQL Java connector, updating to the ColdFusion JDK/JRE LTS release, reviewing serial filter protections against insecure deserialization, and following the ColdFusion Security documentation and relevant Lockdown Guide recommendations.

Administrators should prioritize inventorying exposed instances, testing and deploying the update through change-control processes, restricting access to the ColdFusion Administrator, reviewing service account privileges, and monitoring logs for anomalous command executions, authentication activities, or unexpected application errors.

CVE Details

CVECWE / Vulnerability categoryImpactSeverityCVSS
CVE-2026-48362CWE-78 OS command injectionArbitrary code executionCritical10.0
CVE-2026-48273CWE-95 Eval injectionArbitrary code executionCritical9.9
CVE-2026-71384CWE-863 Incorrect authorizationApplication denial-of-serviceCritical9.6
CVE-2026-71386CWE-79 Cross-site scriptingArbitrary code executionCritical8.8
CVE-2026-71387CWE-863 Incorrect authorizationArbitrary code executionCritical8.8
CVE-2026-21273CWE-20 Improper input validationPrivilege escalationCritical8.7
CVE-2026-71385CWE-863 Incorrect authorizationSecurity feature bypassCritical8.4
CVE-2026-34635CWE-321 Hard-coded cryptographic keySecurity feature bypassCritical8.2
CVE-2026-48440CWE-122 Heap-based buffer overflowArbitrary code executionCritical8.1
CVE-2026-21279CWE-20 Improper input validationSecurity feature bypassCritical8.1
CVE-2026-25652CWE-863 Incorrect authorizationPrivilege escalationCritical7.8
CVE-2026-48386CWE-327 Broken or risky cryptographic algorithmMemory exposureCritical7.5
CVE-2026-71383CWE-863 Incorrect authorizationSecurity feature bypassImportant7.3
CVE-2026-48375CWE-863 Incorrect authorizationApplication denial-of-serviceImportant6.5
CVE-2026-48376CWE-116 Improper encoding or escaping of outputSecurity feature bypassImportant5.4
CVE-2026-48384CWE-20 Improper input validationSecurity feature bypassImportant4.9

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News